Wednesday, September 9, 2026

"Chinese-linked IP address, even passwords stolen"...Financial Supervisory Service launches inspections of Koem Payments and Toss Payments

Input
2026-09-09 16:29:12
Updated
2026-09-09 16:29:12
Hacking incident concept image. AP Newsis
[Financial News] Evidence has emerged that a hacker presumed to be Chinese attacked a domestic payment gateway (PG) company, potentially exposing credit card passwords.
According to financial authorities on the 9th, the Financial Supervisory Service shifted its recent on-site inspections of Koem Payments and Toss Payments to formal inspections that day.
An official from the Financial Supervisory Service said, "We had been conducting on-site inspections of the two PG companies, but shifted to formal inspections starting today."
According to a notice posted by Koem Payments on its website, the hacking attack occurred between 8:13 a.m. on the 30th of last month and 5:34 a.m. on September 1. Koem Payments said it became aware of the incident at 8 a.m. on September 2.
The attack may have exposed customers’ card numbers and expiration dates, as well as birth-date-related information and card passwords.
Koem Payments said, "As we currently do not possess the individual transaction records and card information obtained by the attacker, we cannot identify the transactions and data subjects actually affected." It added, "Given the structure of the payment-request messages processed by the compromised system, card numbers and expiration dates may have been included. For some payment methods, birth-date-related information and the first two digits of card passwords may also have been included, and we are working with the relevant authorities to verify the exact details."
Toss Payments explained that the incident was not caused by hacking or a vulnerability attack against its system. A Toss Payments official said, "The authentication credentials for the website of one specific merchant using Toss Payments’ PG service—the integration key—were exposed, and a third party used them to view payment records." The official added, "The impact was limited to the payment records of that one merchant."
The confirmed scope of credit card information accessed covers 4,131 transactions involving 2,671 individuals. However, Toss Payments said that information required to make payments, including card passwords, expiration dates, and CVCs, was not included. Notifications of the data breach have been completed for all affected users.
The incident is presumed to have involved an attack by a Chinese hacker, and the hacker reportedly disclosed the breach before the authorities and the affected companies did.
However, financial authorities say it is too early to conclude that the hacker was Chinese. An official from the Financial Supervisory Service said, "Based on our tracking of the IP address and other information so far, the source appears to be China-linked, but there are many ways to route IP addresses through intermediaries, making it difficult to determine the hacker’s nationality."
[email protected] Park Moon-soo Reporter